CVE-2026-76460

Received
Published: 16 Sept 2026, 20:12
Last modified:17 Sept 2026, 03:57

Vulnerability Summary

Overall Risk (default)
high
70/100
CVSS Score
10 CRITICAL
v3.1 (cve.org)
EPSS Score
No data
KEV
Listed
CISA
1 listing
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

16 Sept 2026, 20:12
Published
Vulnerability first disclosed
16 Sept 2026, 00:00
Added to CISA KEV
Cisco Identity Services Engine Incorrect Use of Privileged APIs Vulnerability
17 Sept 2026, 03:57
Last Modified
Vulnerability information updated
19 Sept 2026, 00:00
CISA Remediation Due
Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

Description

A vulnerability in an API of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to bypass authentication. This vulnerability is due to insufficient authentication control on an API endpoint. An attacker could exploit this vulnerability by sending a crafted request to an affected API endpoint. A successful exploit could allow the attacker to gain unauthorized access to the affected device by bypassing the web-based management interface.

CVSS Metrics

  • v3.1CRITICALScore: 10CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

Techniques & Countermeasures

  • CWE-648Incorrect Use of Privileged APIs

    The product does not conform to the API requirements for a function call that requires extra privileges. This could allow attackers to gain privileges by causing the function to be called incorrectly.

Affected Systems

  • ciscocisco identity services engine software

    3.1.0 p8 | 3.1.0 p9 | 3.3 Patch 2 | 3.3 Patch 1 | 3.3 Patch 3 | 3.4.0 | 3.2.0 p7 | 3.3 Patch 4 | 3.4 Patch 1 | 3.1.0 p10 | 3.3 Patch 5 | 3.3 Patch 6 | 3.4 Patch 2 | 3.3 Patch 7 | 3.4 Patch 3 | 3.5.0 | 3.4 Patch 4 | 3.3 Patch 8 | 3.2 Patch 8 | 3.5 Patch 1 | 3.3 Patch 9 | 3.2 Patch 9 | 3.4 Patch 5 | 3.5 Patch 3 | 3.5 Patch 2 | 3.3 Patch 10 | 3.3 Patch 11 | 3.4 Patch 6 | 3.2 Patch 10 | 3.1.0 p11

  • ciscocisco ise passive identity connector

    3.4.0 | 3.5.0

References (2)